Staff Security Engineer
On-siteCopenhagen, Capital Region, Denmark
Job Summary
Design and build security tooling for image scanning, SBOM generation, and CVE response within existing pipelines, routing findings to owners under tracked SLAs. Lead the design, reviews, and tooling for a unified internal network and VPN across GCP, AWS, and offices in Miami, Berlin, and Copenhagen. Work with auth service maintainers on identity and access, including MFA rollouts and token lifecycle management. Make workload identity the standard for CI/CD using OIDC between GitHub Actions and cloud providers. Build shared audit logging and turn GRC controls into technical implementations with automated evidence pipelines. Own the contracting cycle for external penetration tests and manage the intake, classification, and tracking system for findings. Hand each capability off cleanly with runbooks, named owners, and escalation paths, while conducting office hours for product and platform teams. Mentor the team to raise the security bar across Builders.
Required Qualifications
- several years of production infrastructure and security experience
- depth and credibility in either platform security or identity and auth
- experience running vulnerability scanning, CVE management, and image scanning at scale
- knowledge of the operational reality of getting CVEs fixed
- hands-on experience inside an auth codebase
- experience rolling out MFA on live systems
- experience managing token lifecycles in CI/CD with OIDC and workload identity
- experience designing and running a unified internal network across multiple cloud providers and offices
- experience with a VPN approach that holds up at scale
- experience building internal security tooling that other teams chose to adopt
- experience with guard rails built into tools developers already use
- experience gathering feedback and measuring the impact of security tooling
- strong experience with Terraform
- strong experience with Crossplane
- experience with similar Infrastructure as Code tools
Desired Qualifications
- experience with GitOps tools such as Flux or ArgoCD
- experience with Cilium
- experience with Kubernetes security at scale
- experience building security into a GRC evidence pipeline
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.